CLI
Command-Line Interface
A text-based interface used to interact with a computer through commands.
Related: cwd, filesystem
Loading HackVora…
Global glossary
Command-Line Interface
A text-based interface used to interact with a computer through commands.
Related: cwd, filesystem
Current Working Directory
The directory in which the current shell command operates.
Related: cli, filesystem
Filesystem
The hierarchy used to organize files and directories.
Related: cwd, permissions
Directory
A filesystem container that organizes files and other directories.
Related: filesystem, path
Filesystem Path
A textual location identifying a file or directory in a filesystem.
Related: cwd, directory, file
File
A named filesystem object that stores data.
Related: filesystem, path
File Permission Mode
The numeric or symbolic representation of permissions on a filesystem object.
Related: permissions, chmod
File Owner
The user account that owns a filesystem object.
Related: group, other
File Group
The group associated with a filesystem object.
Related: owner, other
Other Users
Users who are neither the owner nor members of the file's group.
Related: owner, group
Read Permission
Permission to view file contents or list a directory.
Related: write, execute
Write Permission
Permission to modify a file or directory contents.
Related: read, execute
Execute Permission
Permission to run a file or traverse a directory.
Related: read, write
Change Mode
A Linux command that changes simulated file permission modes.
Related: file-mode, numeric-permissions, symbolic-permissions
Numeric Permission Notation
Permission notation using octal digits from 0 through 7.
Related: file-mode, chmod
Symbolic Permission Notation
Permission notation using class, operation, and permission letters such as u+x.
Related: file-mode, chmod
File Permissions
Rules controlling who may read, write, or execute a filesystem object.
Related: least-privilege, filesystem
Principle of Least Privilege
Grant only the access required to perform an authorized task.
Related: permissions
Internet Protocol Address
An address assigned to a network interface for identification and routing within an IP network.
Related: ipv4, ipv6, network-interface
Internet Protocol version 4
An IP addressing format commonly written as four decimal octets.
Related: ip-address, private-ip
Internet Protocol version 6
A newer IP protocol with 128-bit addresses commonly written in hexadecimal groups.
Related: ip-address, ipv4
Private Internet Protocol Address
An address from a range reserved for private networks and not globally routed on the public Internet.
Related: public-ip, ipv4
Public Internet Protocol Address
An IP address that is not in a private range; this classification alone does not prove direct Internet reachability.
Related: private-ip, ip-address
Media Access Control Address
A link-layer identifier associated with a network interface.
Related: network-interface
User Datagram Protocol
A connectionless transport protocol with low overhead that does not provide TCP-style ordered delivery guarantees.
Related: tcp, port
Domain Name System
The distributed naming system that maps names to records such as IP addresses.
Related: resolver, ip-address
DNS Resolver
A component that requests and processes DNS information for clients.
Related: dns
Default Gateway
A router address used as a first hop for destinations outside a host's directly connected network.
Related: router, routing
Network Router
A device or software function that forwards packets between IP networks.
Related: gateway, routing
IP Routing
The process of selecting a path and forwarding packets toward another network.
Related: router, gateway
Network Interface
A physical or virtual endpoint through which a host connects to a network.
Related: ip-address, mac-address
Computer Network
A group of devices or services able to communicate through shared networking technologies.
Related: client, server, protocol
Network Protocol
A defined set of rules used by systems to exchange information.
Related: tcp, udp, http
Network Client
A system or application that initiates a request for a service.
Related: server, source-port
Network Server
A system or application that listens for and responds to client requests.
Related: client, destination-port
Transport Layer Security
A protocol that protects data exchanged between applications, including HTTPS connections.
Related: https, tcp
Network Socket
A communication endpoint commonly described using an address, port, and protocol.
Related: ip-address, port, protocol
Connection Source Port
The port associated with the system initiating or sending one side of a connection.
Related: destination-port, socket
Connection Destination Port
The port identifying the service endpoint receiving traffic in a connection.
Related: source-port, port
IP Subnetwork
A logical subdivision of an IP network, represented here by prefixes such as /24.
Related: ip-address, gateway
Network Hostname
A human-readable name assigned to a host and potentially mapped to an address through DNS.
Related: dns, ip-address
Internet Protocol
The protocol responsible for addressing and routing packets between networks.
Related: tcp, port
Transmission Control Protocol
A reliable, ordered, connection-oriented transport protocol.
Related: ip, port, http
Network Port
A numeric endpoint identifying a network service on a host.
Related: tcp, http
Hypertext Transfer Protocol
The request-response application protocol used by the web.
Related: url, tcp
Uniform Resource Locator
An address that identifies where a resource can be accessed.
Related: http
Hypertext Transfer Protocol Secure
HTTP exchanged over a transport protected with TLS.
Related: http, url
Uniform Resource Identifier
A string that identifies a resource; a URL is a kind of URI that also describes its location.
Related: url
Hypertext Transfer Protocol Method
The request token describing the action semantics, such as GET or POST.
Related: http, request-header
HTTP Request Header
A named metadata field sent with an HTTP request.
Related: request-body, user-agent, authorization
HTTP Request Body
Optional content sent after request headers, such as fictional JSON form data.
Related: request-header, content-type
HTTP Response
A server's simulated reply containing a status, headers, and optional body.
Related: status-code, content-type
HTTP Response Status Code
A three-digit code summarizing an HTTP response outcome.
Related: response, redirect
URL Query Parameter
A key-value item in the query component after a URL's question mark.
Related: url, uri
HTTP Cookie
A small value a server asks a browser to store and potentially return in later requests.
Related: session, request-header
Application Session
Application state associated with a sequence of requests, often referenced through a cookie identifier.
Related: cookie
HTTP User-Agent Header
A request header that describes the client software making the request.
Related: request-header
HTTP Content-Type Header
A header describing the media type of a request or response body.
Related: request-body, response
HTTP Cache-Control Header
A header carrying directives for HTTP caching behavior.
Related: response
Access Authorization
The process of determining which actions or resources an authenticated identity may access; HTTP may carry authorization information in a request header.
Related: request-header, authentication
HTTP Redirect
A response directing a client toward another location, commonly represented by a 3xx status and Location header.
Related: status-code, url
HTTP Request
A message a client sends to a server containing a method, target, headers, and optional body.
Related: response, http-method
HTTP Response Header
A named metadata field returned with an HTTP response.
Related: response, response-body
HTTP Response Body
Optional content returned after an HTTP response's headers.
Related: response-header, content-type
HTTP GET Method
An HTTP method commonly used to retrieve a representation of a resource.
Related: http-method, request
HTTP POST Method
An HTTP method commonly used to submit data for processing or resource creation.
Related: http-method, request-body
HTTP PUT Method
An HTTP method commonly used to replace a resource representation.
Related: http-method
HTTP PATCH Method
An HTTP method commonly used to apply a partial resource update.
Related: http-method
HTTP DELETE Method
An HTTP method commonly used to request removal of a resource.
Related: http-method
URL Scheme
The URL component describing how a resource is addressed, such as http or https.
Related: url, https
HTTP Host
The destination hostname identified by a URL or Host request header.
Related: url, request-header
URL Path
The URL component identifying a resource location on the destination host.
Related: url, query-parameter
HTTP Content-Length Header
A header indicating a message body's size in bytes.
Related: response-header, request-body
HTTP Success Status Class
HTTP status codes from 200 through 299 indicating successful handling.
Related: status-code
HTTP Redirection Status Class
HTTP status codes from 300 through 399 describing redirection outcomes.
Related: status-code, redirect
HTTP Client Error Status Class
HTTP status codes from 400 through 499 describing client-side request errors.
Related: status-code
HTTP Server Error Status Class
HTTP status codes from 500 through 599 describing server-side errors.
Related: status-code
Network Mapper
A network exploration tool represented only through prerecorded fictional output in this room.
Related: scan, host-discovery
Open Network Port
A scan state indicating that the scanner observed a service accepting communication at a port.
Related: closed-port, filtered-port
Closed Network Port
A scan state indicating the target responded but no service was observed listening at that port.
Related: open-port, filtered-port
Filtered Network Port
A scan state indicating that the scanner could not determine whether a port was open; it does not prove a firewall exists.
Related: open-port, closed-port
System or Network Service
An application function managed by a system or associated with a network endpoint.
Related: port, service-detection, daemon
Network Service Detection
The process of estimating which service or product is associated with a network endpoint.
Related: service, version-detection
Service Version Detection
The process of estimating a service product and version; an observation is not proof of vulnerability.
Related: service-detection
Network Host Discovery
The concept of determining which hosts appear reachable, represented here only with fictional data.
Related: scan, nmap
Network Scan
A set of observations about fictional hosts and ports in this educational room.
Related: nmap, port
Network-Accessible Service
An application function made available through a network protocol and port.
Related: service, port
System Log
A record of events generated by software or systems for monitoring, troubleshooting, auditing, and investigation.
Related: event, log-entry
Recorded Event
An occurrence recorded by a system or application with contextual information.
Related: log, log-entry
Identity Authentication
The process of verifying an asserted identity.
Related: authorization, successful-authentication, failed-authentication
Failed Authentication Event
A recorded authentication attempt that did not successfully verify an identity.
Related: authentication, successful-authentication
Successful Authentication Event
A recorded authentication event in which identity verification succeeded according to the log evidence.
Related: authentication, failed-authentication
Source Internet Protocol Address
The IP address recorded as the source of a fictional network event.
Related: ip-address, event-correlation
Security Event Correlation
Connecting related observations across events or log sources without exceeding the evidence.
Related: event, soc
Individual Log Entry
A single recorded event containing fields such as timestamp, host, service, and message.
Related: log, event
Log Severity Level
A label indicating the reported severity or importance of an event.
Related: log-entry
Security Audit Log
A log intended to preserve activity records for accountability and review.
Related: log, authentication
Secure Shell
A protocol for secure remote access, represented only through fictional authentication events in this room.
Related: sshd, authentication
Secure Shell Daemon
The server process that handles SSH connections and emits fictional authentication records in this simulation.
Related: ssh, authentication
Security Operations Center
A team or function responsible for monitoring and investigating security events.
Related: event-correlation, ioc
Indicator of Compromise
An observable artifact that may support an investigation but requires context and validation.
Related: soc, event-correlation
System Troubleshooting
A structured process of observing symptoms, gathering evidence, forming hypotheses, acting, and verifying results.
Related: evidence, hypothesis, verification
Background Service Process
A background process that provides a system service.
Related: service, systemd
Linux System and Service Manager
A Linux service manager represented through fictional status and journal output in this room.
Related: systemctl, journalctl
systemd Control Command
A command used to inspect or manage systemd units; this room only simulates status output.
Related: systemd, service-state
systemd Journal Query Command
A command used to inspect the systemd journal; all room results are prerecorded.
Related: systemd, log
Service Configuration
Settings that control application or service behavior.
Related: service, troubleshooting
Service Dependency
A service or resource another application needs to function.
Related: service, service-state
Filesystem Disk Usage
The amount or percentage of simulated storage currently used.
Related: filesystem
Filesystem Permission
A rule affecting whether an identity may access a filesystem object.
Related: ownership, permissions
File Ownership
The user and group associated with a filesystem object.
Related: permission, root-user
Linux Superuser
The privileged Linux account commonly named root.
Related: ownership, permission
Process Exit Status
A numeric status produced when a process ends; a nonzero value commonly indicates an error.
Related: service-state
System Service State
The reported condition of a service, such as active, inactive, or failed.
Related: service, systemctl
Operational or Security Incident
An event or disruption requiring structured investigation and response.
Related: evidence, remediation
Investigation Evidence
Observed information that supports or challenges an investigation hypothesis.
Related: hypothesis, verification
Troubleshooting Hypothesis
A testable explanation for observed symptoms based on available evidence.
Related: evidence, verification
Corrective Remediation
A corrective action selected after evidence supports the likely cause.
Related: incident, verification
Post-Remediation Verification
Checking that service health and user-visible behavior recovered after a simulated action.
Related: remediation, evidence
Brute-Force Authentication Pattern
A repeated authentication-attempt pattern requiring investigation; log evidence alone does not prove source identity or intent.
Related: authentication-failure, detection-signal
Failed Identity Verification
An event indicating an authentication attempt did not succeed.
Related: failed-authentication, target-account
Targeted User Account
The username referenced by an authentication attempt.
Related: authentication, source-ip
Security Event Frequency
The count or rate of related events within a defined interval.
Related: time-window, detection-signal
Detection Time Window
The interval between the first and last event considered in an analysis.
Related: event-frequency
Security Detection Signal
A pattern of observations that merits investigation but is not automatic proof of malicious activity.
Related: alert, false-positive
Security Alert
A notification that a predefined observation or pattern requires analyst review.
Related: triage, escalation
Security Alert Triage
The initial process of validating, contextualizing, and prioritizing an alert.
Related: alert, evidence
Security Case Escalation
Passing an evidence-supported observation for deeper investigation or response.
Related: alert, evidence
False-Positive Detection
An alert that appears suspicious but is explained as benign after investigation.
Related: detection-signal, triage
Security Alert Triage
The workflow used to validate, contextualize, prioritize, and disposition a security alert.
Related: alert, investigation
Alert Severity
An estimate of how serious an alert's underlying event could be.
Related: priority
Investigation Priority
How urgently an alert should be handled after considering severity and context.
Related: severity, critical-asset
True-Positive Detection
An alert supported by evidence as matching the activity its detection intended to identify; intent may still be unknown.
Related: false-positive, evidence
Security Investigation
A structured examination of evidence and context to assess an alert without exceeding known facts.
Related: evidence, alert-triage
Alert Context
Relevant surrounding facts such as asset criticality, maintenance, users, timing, and expected activity.
Related: evidence, priority
Security Analyst
A person who validates and investigates security signals and documents evidence-based conclusions.
Related: analyst-note, soc
Security Analyst Note
A concise record of observations, evidence, assessment, and next action.
Related: analyst, evidence
Security Detection
Logic or a process that produces a signal when observed activity matches defined conditions.
Related: alert, security-event
Recorded Security Event
A recorded occurrence relevant to security monitoring or investigation.
Related: detection, event-correlation
Business-Critical Asset
A system or resource whose disruption or compromise could have significant impact.
Related: priority, severity
Approved Maintenance Window
An authorized period in which planned technical activity is expected to occur.
Related: benign-activity, alert-context
Expected Benign Activity
Observed activity supported by context as legitimate or expected after validation.
Related: false-positive, maintenance-window
Phishing Social Engineering
A social-engineering technique that attempts to influence a recipient into revealing information or taking an action.
Related: social-engineering, spear-phishing
Targeted Phishing
Phishing tailored toward a particular person, role, or organization.
Related: phishing, recipient
Social Engineering
Influencing people into disclosing information or taking actions through deceptive or manipulative communication.
Related: phishing
Email Sender
The address and associated identity information presented as the source of an email.
Related: reply-to, return-path
Email Recipient
A user or mailbox addressed in the To, CC, or BCC fields of a message.
Related: sender, email-header
Reply-To Header
An email header suggesting where replies should be directed, which may differ from the From address.
Related: sender, email-header
Return-Path Header
A header recording an address used for email delivery status and bounce processing.
Related: sender, email-header
Email Message Header
Structured message metadata including sender, recipients, routing, and authentication results.
Related: sender, recipient, spf, dkim, dmarc
Sender Policy Framework
An email-authentication mechanism that checks whether a sending system is authorized for a domain.
Related: dkim, dmarc
DomainKeys Identified Mail
An email-authentication mechanism using a cryptographic signature associated with a domain.
Related: spf, dmarc
Domain-based Message Authentication, Reporting, and Conformance
A domain policy framework that uses SPF and DKIM alignment and defines handling and reporting expectations.
Related: spf, dkim
Email Attachment
A file represented as part of an email; this room displays only inert fictional metadata and never opens files.
Related: email-security, indicator
Internet Domain Name
A hierarchical name used in addresses such as email sender domains and URL destinations.
Related: url, lookalike-domain
Visually Similar Domain
A domain spelled to resemble another name; similarity is an indicator requiring context, not proof by itself.
Related: domain, sender
Email Security
Practices and controls used to assess and protect email communication.
Related: phishing, email-header
Investigation Indicator
An observable detail that may support an assessment when combined with evidence and context.
Related: evidence, phishing
Malicious Software
Software intended to cause harm or unauthorized effects; this room uses no real malware.
Related: malware-triage, static-analysis
Initial Malware Triage
A cautious initial review used to decide whether an artifact deserves deeper analysis and to collect supporting evidence.
Related: artifact, assessment
Static File Analysis
Inspection of file properties and content without executing the file.
Related: dynamic-analysis, file-metadata
Behavioral Dynamic Analysis
Analysis of behavior during controlled execution; it is explained but never performed in this room.
Related: static-analysis
Investigation Artifact
A file, record, or other observable item preserved for investigation.
Related: evidence, indicator
Cryptographic Hash
A deterministic fingerprint used to identify or compare content, not to prove maliciousness.
Related: sha-256, md5
Secure Hash Algorithm 256-bit
A cryptographic hash algorithm commonly used to identify exact file content.
Related: hash
Message-Digest Algorithm 5
A legacy content hash still encountered as an identifier; it is not evidence of maliciousness by itself.
Related: hash, sha-256
File System Metadata
Descriptive file properties such as type, size, and timestamps that provide evidence and context.
Related: file-extension, artifact
Filename Extension
The final suffix of a filename commonly used to indicate its format or handling.
Related: executable, file-metadata
Portable Executable
A file format used by Windows executables and related files; format alone does not establish intent.
Related: executable
Static File String
A readable text sequence observed in a file that may provide an investigation lead.
Related: static-analysis, indicator
Executable File
A file format designed to contain instructions a system can run; this room never runs one.
Related: pe, file-extension
Operating System Process
A running instance of a program; process names may serve as investigation artifacts.
Related: executable, indicator
Initial Security Assessment
A cautious evidence-based judgment that records uncertainty and appropriate next steps.
Related: evidence, suspicious
Benign-Appearing
Appearing consistent with expected harmless activity based on current evidence, without an absolute guarantee.
Related: false-positive, assessment
Suspicious Artifact
Displaying indicators that justify further investigation without alone proving maliciousness.
Related: assessment, indicator
Network Interface State
The reported condition of an interface, such as UP or DOWN.
Related: network-interface
Network Route
A rule describing where traffic for a destination should be sent.
Related: routing-table, gateway
IP Routing Table
A collection of routes used to select paths toward destinations.
Related: route, gateway
DNS Name Resolution
The process of mapping a hostname to information such as an IP address.
Related: dns
Network Connectivity
The ability of systems or services to exchange traffic across a network path.
Related: timeout, route
Connection Timeout
An operation ending because no sufficient response arrived within its allowed interval; several causes remain possible.
Related: connectivity, connection-refused
Refused Network Connection
A response indicating the destination did not accept the connection at that service endpoint.
Related: service-availability, port
HTTP 404 Not Found
An HTTP response indicating that the requested resource was not found.
Related: status-code, application-layer
HTTP 503 Service Unavailable
An HTTP response indicating that the server cannot currently provide the requested service.
Related: service-availability, application-layer
Network Service Availability
Whether an application service is currently able to accept and fulfill requests.
Related: connection-refused, http-503
Application Protocol Layer
The layer containing application protocols and services such as HTTP and HTTPS.
Related: transport-layer, http
Transport Protocol Layer
The layer using protocols such as TCP and UDP to carry application communication.
Related: network-layer, tcp, udp
Internet Protocol Layer
The layer responsible for IP addressing and routing between networks.
Related: transport-layer, route
Underlying Cause
The underlying condition that best explains an observed problem based on evidence.
Related: hypothesis, diagnostic
Diagnostic Evidence
A check or observation used to narrow possible explanations for a symptom.
Related: evidence, hypothesis